Description
The 1180px Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortcode attribute in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-01-07
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting via contributor‑level access
Action: Apply Patch
AI Analysis

Impact

The 1180px Shortcodes plugin for WordPress is vulnerable because the value supplied to the ‘class’ attribute of its shortcodes is not properly sanitized or escaped. Authenticated users with Contributor or higher privileges can store malicious scripts that will execute for every visitor who accesses a page containing the affected shortcode. This stored cross‑site scripting can lead to credential theft, session hijacking, defacement, or delivery of additional malware, compromising the confidentiality, integrity, and availability of site visitors.

Affected Systems

WordPress installations that have the 1180px Shortcodes plugin from chrisblackwell, with version 1.1.1 or any earlier release, are affected. All releases up to and including 1.1.1 contain the vulnerable code path.

Risk and Exploitability

The CVSS score of 6.4 indicates moderate severity, while an EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires authenticated access with Contributor or higher privileges, making the attack vector internal. Once an attacker stores a payload, it persists and is delivered to every site visitor until the vulnerability is remediated.

Generated by OpenCVE AI on April 21, 2026 at 00:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the 1180px Shortcodes plugin to a version newer than 1.1.1 to eliminate the vulnerable code path.
  • Limit or remove Contributor and higher roles from untrusted users or adjust capabilities to restrict the creation of malicious shortcodes.
  • If upgrading is not immediately possible, use a theme or plugin filter to strip or neutralize the ‘class’ attribute from existing shortcodes before rendering the page.

Generated by OpenCVE AI on April 21, 2026 at 00:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Jan 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Wed, 07 Jan 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Jan 2026 09:30:00 +0000

Type Values Removed Values Added
Description The 1180px Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortcode attribute in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title 1180px Shortcodes <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class' Shortcode Attribute
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:28:12.469Z

Reserved: 2025-12-05T15:04:16.291Z

Link: CVE-2025-14114

cve-icon Vulnrichment

Updated: 2026-01-07T14:47:06.489Z

cve-icon NVD

Status : Deferred

Published: 2026-01-07T12:16:52.700

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-14114

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-21T00:30:22Z

Weaknesses